Detection EngineeringOctober 8, 2026

Sysmon Event ID 11: File Create Explained

Sysmon Event ID 11 logs file creation and overwrite. Learn its fields, the payload drops and persistence it catches, plus Splunk and KQL searches.

ET

EpicDetect Team

7 min read

Sysmon Event ID 11: File Create Explained

Sysmon Event ID 11: File Create Explained

Sysmon Event ID 11 is the FileCreate event. Sysmon writes it when a process creates a file or overwrites an existing one, and it tells you which process did it and where the file landed. If you want to know what an attacker dropped on a machine, this is the first place to look.

Microsoft's own description is short: it is useful for monitoring autostart locations like the Startup folder, plus temporary and download directories, which are common places malware drops files during initial infection. This post covers the fields, the attack patterns, searches you can paste into Splunk and Sentinel, and the noise you will have to tune out. For all the IDs side by side, see our Sysmon Event IDs cheat sheet.

What Sysmon Event ID 11 logs

Event 11 is created when a file is created or overwritten. It does not log every write, every read, or every time a file is opened. If a process appends to a file that already exists, you should not expect an Event 11 for it. Think of it as "a file came into existence here" rather than "a file was touched".

The fields you will use most:

  • Image: the full path of the process that created the file. This answers "who wrote it?" and is usually the most important field.
  • TargetFilename: the full path and name of the file that was created. This answers "where did it land, and what is it called?"
  • CreationUtcTime: the file's creation time. Compare it with the event's UtcTime to spot timestamps that look wrong.
  • UtcTime: when Sysmon recorded the event. Sysmon timestamps are in UTC.
  • ProcessGuid and ProcessId: link the file drop back to the process in your Event ID 1 (process creation) record. Prefer the GUID, because Windows reuses process IDs.
  • User: the account that ran the process, on Sysmon versions that include it.
  • RuleName: shows which rule in your config matched, if you named your rules.

What gets logged depends on your Sysmon configuration. A bare install with no config does not give you what a tuned config does. Community configs such as SwiftOnSecurity's and Olaf Hartong's sysmon-modular decide which paths and file types produce Event 11, so check your own config before you assume that silence means nothing happened. Logging every file create on a busy machine is far too noisy, so most configs use include rules for risky locations or file types.

What it catches

Payloads dropped to user-writable folders

Attackers need somewhere they can write without admin rights. That means folders like C:\Users\<name>\AppData\Local\Temp, AppData\Roaming, C:\Users\Public and Downloads. An executable, DLL or script created there by an unexpected process is worth a look.

EventCode=11
Image: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
TargetFilename: C:\Users\Public\update.exe
CreationUtcTime: 2026-10-08 09:14:22.317

A PowerShell process writing an .exe into C:\Users\Public is not something a normal user does by hand. Follow it with Event ID 1 to see whether update.exe then ran. If the file came from the internet, the related ATT&CK technique is Ingress Tool Transfer (T1105).

Files written to Startup folders for persistence

Anything placed in a user's Startup folder runs at logon. Event 11 is a good way to catch that file being written.

Image: C:\Windows\System32\cmd.exe
TargetFilename: C:\Users\jsmith\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sync.lnk

Watch for the user Startup path above and the all-users one under C:\ProgramData\Microsoft\Windows\Start Menu\Programs\StartUp. This maps to Boot or Logon Autostart Execution: Startup Folder (T1547.001).

Script and executable drops by Office or browsers

Word, Excel and browsers write files all day, but they rarely write scripts or executables. When they do, pay attention.

Image: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
TargetFilename: C:\Users\jsmith\AppData\Local\Temp\invoice.js

A macro or exploit in a document that drops a .js, .vbs, .hta, .ps1, .dll or .exe is a classic step after a phishing email. A browser writing an .exe into Downloads is normal when someone installs software, so check what the user was doing and what ran next.

Searching for it

Both searches below are starting points. Adjust paths and extensions for your environment.

Splunk

This assumes Sysmon data is in sourcetype="XmlWinEventLog:Microsoft-Windows-Sysmon/Operational" and that you use the Splunk Add-on for Sysmon, which extracts Image, TargetFilename and the other fields.

sourcetype="XmlWinEventLog:Microsoft-Windows-Sysmon/Operational" EventCode=11
(TargetFilename="*\\AppData\\*" OR TargetFilename="*\\Users\\Public\\*" OR TargetFilename="*\\Temp\\*")
(TargetFilename="*.exe" OR TargetFilename="*.dll" OR TargetFilename="*.ps1" OR TargetFilename="*.js" OR TargetFilename="*.vbs" OR TargetFilename="*.hta")
| stats count values(TargetFilename) AS files BY host, Image
| sort - count

This finds executable and script files created in user-writable folders and groups them by host and creating process, so unusual Images stand out. More patterns are in our SPL cheat sheet.

KQL (Microsoft Sentinel)

This assumes Sysmon is forwarded into the Event table, with the fields sitting inside EventData. We pull the two fields out with a simple regex.

Event
| where Source == "Microsoft-Windows-Sysmon" and EventID == 11
| extend Image = extract(@'<Data Name="Image">([^<]*)</Data>', 1, EventData)
| extend TargetFilename = extract(@'<Data Name="TargetFilename">([^<]*)</Data>', 1, EventData)
| where TargetFilename has_any (@"\Startup\", @"\Users\Public\", @"\AppData\", @"\Temp\")
| where TargetFilename endswith ".exe" or TargetFilename endswith ".dll" or TargetFilename endswith ".ps1" or TargetFilename endswith ".js" or TargetFilename endswith ".vbs" or TargetFilename endswith ".lnk"
| project TimeGenerated, Computer, Image, TargetFilename

This lists risky file types written to risky folders, with the process that wrote them.

False positives

Event 11 in user folders is noisy, because normal software does the same thing.

  • Software updaters: Chrome, Edge, Teams, Slack and Zoom write executables and DLLs under AppData all the time. Build an allowlist by Image and path, and check that the file is signed.
  • Installers and IT tools: Deployment tools drop files in Temp. If the process is your known deployment agent and the timing matches a change window, it is probably fine.
  • Browser downloads: A browser creating an .exe in Downloads is expected. Ask what the user was doing, and whether it ran afterwards.
  • Temp files from Office: Office creates many temporary files. Script and executable types are the ones to watch.

To tell good from bad, ask three questions. Is this Image normally the one writing this kind of file? Is the location normal for it? Did the file then execute? If the answer to the third is yes and the first two are no, escalate.

How it fits with other Sysmon events

Event 11 tells you a file arrived. The other events tell you the rest of the story.

  • Event ID 1 (process creation): Did the dropped file run? Match TargetFilename to a later Image. See Sysmon Event ID 1.
  • Event ID 3 (network connection): Did the process that wrote the file also reach out to the internet? See Sysmon Event ID 3.
  • Event ID 15 (file stream hash): Logs named streams such as the Zone.Identifier mark of the web, which helps show a file came from a browser download.
  • Event ID 23 and 26 (file delete): Attackers often delete what they dropped. These show the cleanup, and Event 23 can archive the deleted file.
  • Event ID 12 and 13 (registry): Persistence is often a file plus a registry Run key.

To practise these pivots, try our endpoint investigation practice guide.

FAQs

What is Sysmon Event ID 11?

It is the FileCreate event. It logs when a process creates or overwrites a file, with the process path in Image and the file path in TargetFilename.

Does Event ID 11 log every file write?

No. It logs creation and overwrite, not every read or modification of an existing file. Your Sysmon config also filters which creates are recorded.

How do I find malware dropped to Temp or AppData?

Search Event 11 for executable and script extensions in those folders, then group by the creating Image. Unusual writers, like PowerShell or Office creating an .exe, are the ones to chase.

What is the difference between Event ID 11 and Event ID 15?

Event 11 logs the file creation. Event 15 logs the creation of a named file stream and hashes its contents, which can capture the Zone.Identifier stream that browsers attach to downloads.

TL;DR

Sysmon Event ID 11 logs file creation and overwrite, showing which Image wrote which TargetFilename. Hunt for executables and scripts in AppData, Temp, Public and Startup folders, and for Office or PowerShell as the writer. Expect noise from updaters and installers, so build allowlists. Always pivot to Event ID 1 to see whether the file ran.

How EpicDetect Can Help

Reading about Sysmon events only gets you so far. Adventures drops you into a story-driven SOC investigation where endpoint evidence like this is how you crack the case. Season Zero is free.

Want the fuller picture? The EpicDetect Atlas maps out what to learn next, from SOC fundamentals to detection engineering.

Tags

SysmonEndpoint InvestigationDetection EngineeringWindowsSOC Analyst

Want to Learn More?

Explore more cybersecurity insights and detection engineering tutorials.